Hosting for FCA-aware fintech teams

Infrastructure that's ready when the regulator is.
Without the FCA badge claims.

We host UK fintech teams that are pre-authorisation, in-authorisation, and post-authorisation under the FCA — payment service providers, e-money issuers, lenders, neo-banks, B2B SaaS for regulated firms. We do not claim authorisation status of our own — we are an infrastructure provider, not a regulated entity. What we provide is the hosting pattern that audit teams and compliance counsel keep asking for: immutable logs, encrypted at rest, documented data flows, written DPA, and a sub-processor list that does not change without notice.

If you are early in your FCA authorisation pathway, this page is the technical pattern your compliance lead can hand to the regulator's PSD2 expert. If you are post-authorisation, this is the operational baseline you do not have to assemble from twelve blog posts. Either way: no claim that we are FCA authorised — we are not. The hosting is.

100 %NVMe enterpriseSamsung PM9A3 / Micron 7400 with DWPD ≥ 1
EUDatacenter locationFrankfurt and Bucharest, UK GDPR aligned
TLS 1.3Transport encryptionEvery connection, no exceptions
LUKSAt-rest encryptionKeys held in HashiCorp Vault
Six concrete things we do

The hosting pattern your compliance lead is going to ask for

Immutable audit logs

All application logs ship to S3-compatible object storage with object-lock enabled — meaning a log written today cannot be modified or deleted before its retention period expires, even by an administrator with root credentials. Standard retention is 7 years, configurable per workload.

S3 + object-lock · 7-year retention · WORM compliance

Encryption at rest with key custody

LUKS encryption on every NVMe device, with keys held in HashiCorp Vault under your control (you can rotate them on a schedule). Database-level encryption (PostgreSQL TDE-style with pgcrypto, or transparent column encryption) available on request for specific PII columns.

LUKS · HashiCorp Vault · pgcrypto · Column-level encryption

PSD2 SCA and 3DS2 friendly

Infrastructure designed to run Strong Customer Authentication workflows reliably: redirect endpoints with sub-200 ms response, OTP delivery via UK SMS aggregators (EE/O2/Vodafone/Three), session state in Redis with low-latency replication, OAuth 2.0 and OIDC stacks pre-configured.

PSD2 SCA · 3DS2 · OAuth 2.0 · OIDC · Sub-200 ms redirect

Disaster recovery with cross-datacenter replica

Production primary in one datacenter, hot or cold replica in another (Frankfurt ↔ Bucharest), failover runbooks documented and tested quarterly. RPO and RTO targets agreed contractually per workload (typical: RPO < 60s, RTO < 15min for tier-1).

Cross-DC replica · Quarterly DR test · RPO < 60s · RTO < 15min

Documented data flows and sub-processors

Every workload comes with a data flow diagram showing where customer data lives, who touches it, and under what contract. Sub-processor list is versioned, notice given 30 days before any change, opt-out available for material changes.

Data flow diagrams · Versioned sub-processor list · 30-day notice

DPA available at signature, signed by our DPO

A Data Processing Agreement under UK GDPR is part of the standard MSA — not an extra-cost add-on. Reviewed by external counsel, aligned with the ICO model clauses, signed by our Data Protection Officer. We can adapt for specific FCA expectations on request.

UK GDPR DPA · ICO model clauses · External counsel reviewed
UK payment methods
Stripe
GoCardless
Faster Payments
BACS
Apple Pay
Google Pay
The questions compliance teams keep asking

FAQ for UK fintech engineering and compliance

Are you FCA authorised?

No. We are an infrastructure provider, not a regulated entity. We host fintech teams that ARE FCA authorised (or working towards it), and we provide hosting patterns that meet the regulator's expectations for systems and controls. Your compliance lead remains responsible for the regulatory status of your firm.

Can you sign our supplier risk assessment?

Yes. We are familiar with the SYSC 8 (Systems and Controls) and outsourcing arrangements expectations in the FCA Handbook. Send us your supplier risk template and we will complete it within 5 working days. We have completed assessments for clients regulated under FCA, PRA, CSSF (Luxembourg) and BaFin (Germany).

What about ISO 27001?

Our EU operating entity is preparing for ISO 27001 certification — we do not currently hold the certificate, so we do not claim it. We follow ISO 27001 Annex A controls operationally; happy to share our ISMS documentation under NDA for due diligence.

Do you support Open Banking sandboxes?

Yes. We have hosted teams testing against the Open Banking sandbox (formerly OBIE, now part of Pay.UK). The hosting pattern is the same as for production: separate environment, separate credentials, separate audit log stream. No special pricing for sandbox environments.

What is the breach notification timeline?

Within 72 hours of detection, as required by UK GDPR. Internal SLA is 12 hours from internal detection. We provide all forensic information needed for your own breach notifications to the ICO and to your FCA supervisor (where applicable).

Scope a setup

Send your supplier risk template. We will fill it in within 5 working days.

Most regulated UK firms have a standardised vendor onboarding template. Send yours, and we will return it completed with our security controls, sub-processor list and DPA appendix attached. No high-pressure sales call afterwards.